Privacy Policy
Last Updated & Effective Date: 3 October 2026 • Rapid Edge Designs Ltd
This document defines the real operational privacy architecture and data processing practices of Rapid Edge Designs Ltd under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018. Formal statutory covenants remain subject to final verification by appointed legal counsel prior to general commercial launch.
1. Identity of Data Controller and Data Processor
Rapid Edge Designs Ltd is a private limited company incorporated in England & Wales under Company Registration Number 17486891, with its registered office located at 66 Paul Street, London, England, EC2A 4NA.
Data Controller Role
Rapid Edge Designs Ltd acts as a Data Controller for personal data collected directly from our business clients, prospective partners, and visitors to rapidedgedesigns.com. This includes business account setup, communications, and Bacs Direct Debit billing administration.
Data Processor Role
For customer inquiries, booking reservations, and contact submissions received through client websites hosted on our Website-as-a-Service (WaaS) platform, Rapid Edge Designs Ltd acts strictly as a Data Processor on behalf of the client pursuant to UK GDPR Article 28. The business client acts as the independent Data Controller.
Supervisory Authority Notification: Information Commissioner's Office (ICO) Registration: pending.
2. Information We Collect
Depending on your relationship with Rapid Edge Designs Ltd, we collect and process the following categories of personal data:
- Business Client Account Details: Representative name, trading name, business registration number, business email address, UK telephone number, and registered or operating address.
- Payment & Billing Data: Bank account holder name, sort code, last two digits of bank account number, and mandate reference IDs processed securely via our FCA-regulated payment partner, GoCardless Ltd, under the Bacs Direct Debit Scheme. We never store full bank credentials on our local servers.
- Tenant Client Inquiries (As Processor): Name, email address, telephone number, and message content submitted by end-users requesting quotes or appointments through client websites.
- Technical & Edge Diagnostic Logs: Anonymized or pseudo-anonymized IP addresses, browser user-agent strings, timestamps, and requested URI resources captured via Amazon CloudFront edge access logs for security monitoring, DDoS mitigation, and diagnostic uptime verification.
3. Lawful Bases for Processing (UK GDPR Article 6)
We process personal data only when an applicable lawful basis exists under Article 6 of the UK GDPR:
Processing necessary to configure and deploy client websites, provision custom domain DNS, execute monthly maintenance routines, and collect agreed retainer subscriptions.
Retention of financial transaction records, invoices, and accounting ledgers in accordance with the Companies Act 2006, Finance Act 1998, and HMRC statutory tax regulations.
Ensuring edge network security, mitigating automated bot abuse via AWS WAF and CloudFront, and diagnosing infrastructure availability.
4. Data Retention, Ephemeral Storage & Automated Purge
We enforce strict data minimization through automated infrastructure lifecycles:
Pursuant to Architectural Decision Record (ADR 0007), customer inquiries submitted through client contact forms are automatically purged from our Amazon DynamoDB datastore 90 days after ingestion using native hardware TTL.
Under Companies Act 2006 s.388 and HMRC tax regulations (FA 1998 Sch 18), commercial billing records and Bacs Direct Debit payment history are retained for 6 years from the end of the financial year and are exempt from tenant purge routines (ADR 0011).
5. Sub-Processors and Data Residency
All core database instances and computing workloads reside in the United Kingdom (AWS London Region: eu-west-2). We engage the following vetted sub-processors:
| Sub-Processor | Service Provided | Data Residency | Safeguard Mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Cloud infrastructure, DynamoDB, S3, CloudFront CDN, WAF | United Kingdom (London eu-west-2) | AWS UK GDPR Addendum / ISO 27001 |
| GoCardless Ltd | Bacs Direct Debit mandate authorization and subscription billing | United Kingdom | FCA-authorised Payment Institution |
| Resend Inc. | Transactional email notification delivery for customer inquiries | United States / Global Edge | UK IDTA / Standard Contractual Clauses |
6. Zero Tracking Cookies & PECR Compliance
Rapid Edge Designs Ltd does not deploy tracking cookies, advertising beacons, or third-party behavioral profiling pixels (such as Google Analytics or Meta Pixel). Because our site uses zero non-essential cookies, no intrusive cookie consent banner is mandated under the Privacy and Electronic Communications Regulations 2003 (PECR) / Schedule A1. For full technical details, consult our Cookie Policy.
7. Data Subject Rights & How to Contact Us
Under the Data Protection Act 2018 and UK GDPR, you have the right to request access to, rectification of, or erasure of your personal data, as well as the right to object to or restrict processing.
To submit a Subject Access Request (SAR) or query our data protection practices, email our compliance team at:privacy@rapidedgedesigns.comor write to our registered office: Rapid Edge Designs Ltd, 66 Paul Street, London, England, EC2A 4NA.
You possess the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF• Tel: 0303 123 1113 • Website: ico.org.uk.